1

Information Risk Manager Jobs in Massachusetts (NOW HIRING)

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This is a hybrid role, 3 days ...

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This is a hybrid role, 3 days ...

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This is a hybrid role, 3 days ...

Obtains information, documents and data from clients to support the completion of analysis and ... Assists with the management of the engagement to ensure engagement metrics are achieved * Utilizes ...

Obtains information, documents and data from clients to support the completion of analysis and ... Assists with the management of the engagement to ensure engagement metrics are achieved * Utilizes ...

Showing results 41-60

Information Risk Manager information

See Massachusetts salary details

$56.2K

$121.8K

$185.7K

How much do information risk manager jobs pay per year?

As of Sep 11, 2026, the average yearly pay for information risk manager in Massachusetts is $121,833.00, according to ZipRecruiter salary data. Most workers in this role earn between $98,300.00 and $140,900.00 per year, depending on experience, location, and employer.

What does an information risk manager do?

An Information Risk Manager is responsible for identifying, assessing, and mitigating risks related to an organization's information assets. They develop and implement risk management policies, conduct regular risk assessments, and ensure compliance with relevant standards and regulations. Their role often involves collaborating with IT, security, and business teams to protect sensitive data and support business continuity. By proactively managing information risks, they help organizations minimize the potential impact of security threats and data breaches.

What are the key skills and qualifications needed to thrive as an information risk manager?

To thrive as an Information Risk Manager, you need expertise in risk assessment, information security principles, and regulatory compliance, often supported by a degree in information technology or cybersecurity and relevant certifications like CISSP or CISM. Familiarity with risk management tools, governance frameworks (such as ISO 27001), and security incident management systems is typical. Strong analytical thinking, communication, and stakeholder management skills help set top performers apart. These capabilities are crucial for proactively identifying, assessing, and mitigating information risks to protect organizational assets and ensure compliance.

What are some common challenges information risk managers face when implementing new risk mitigation strategies?

Information Risk Managers often encounter resistance to change from employees and stakeholders when introducing new risk mitigation strategies. Balancing security requirements with business objectives can also be challenging, as overly restrictive controls may hinder productivity. Additionally, staying updated with evolving cyber threats and ensuring compliance with various regulatory standards requires continuous learning and adaptation. Successful Information Risk Managers proactively communicate the value of risk initiatives and foster collaboration across departments to achieve buy-in.

What is the difference between Information Risk Manager vs Cybersecurity Analyst?

AspectInformation Risk ManagerCybersecurity Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISMCISSP, CompTIA Security+, CEH
Work EnvironmentRisk assessment, policy development, compliance managementSecurity monitoring, incident response, vulnerability assessment
Employer & IndustryFinancial, healthcare, government, large enterprisesIT firms, security service providers, corporate IT teams

The main difference is that an Information Risk Manager focuses on identifying, assessing, and managing overall information risks and compliance strategies, while a Cybersecurity Analyst primarily handles security monitoring, threat detection, and incident response. Both roles require similar certifications and often work within the same industries, but their core responsibilities differ in scope and focus.

Risk Advisory Practice Lead (Tewksbury)

Tewksbury, MA • On-site

Full-time

This job post has expired 2 days ago. Applications are no longer accepted.


Job description

Baker Tilly’s Risk Advisory practice seeks a Principal to lead and grow the national practice in risk, governance, internal audit, IT and cybersecurity services. The role emphasizes entrepreneurship, client service excellence, and strategic leadership within a fast-growing firm.

Responsibilities include directing services, expanding client base, mentoring teams, and delivering high-impact reports while ensuring profitability and strong risk management across client engagements.

#J-18808-Ljbffr